CONSCTLX.exe is a 64-bit backdoor/persistent downloader delivered as part of a multi-stage supply-chain compromise of MicroWorld Technologies’ eScan antivirus update infrastructure on January 20, 2026. Attackers distributed a trojanized “routine” eScan update via a breached regional update server/cluster (reported as a limited two-hour window for affected customers), replacing a legitimate eScan component (32-bit Reload.exe) to initiate execution. The modified Reload.exe dropped CONSCTLX.exe and other stages, which then attempted persistence and payload retrieval.
Capabilities/behavior directly described include: acting as a persistent downloader/backdoor; establishing persistence via scheduled tasks (unexpected tasks under C:\Windows\Defrag\ with names such as Windows\Defrag\CorelDefrag / TrelloDefrag) and registry-based persistence (random GUID-named keys under HKLM\Software\ containing an encoded PowerShell payload stored as a byte array); executing PowerShell; connecting outbound to attacker-controlled command-and-control infrastructure to retrieve additional payloads; and sabotaging eScan’s ability to update/remediate by tampering with eScan registry settings/configuration and modifying the Windows HOSTS file to block access to eScan update servers (effectively “bricking” update functionality and preventing automatic remediation).
Associated incident/attribution: no threat actor attribution is provided in the content for the 2026 incident. (A separate note mentions that in 2024 North Korean hackers were observed exploiting eScan’s updating mechanism, but this is not stated as attribution for CONSCTLX.exe in 2026.)
Targets/impact: eScan Enterprise and Consumer endpoints that pulled updates from the affected eScan update infrastructure during the compromise window; Morphisec described global distribution via legitimate update channels.
High-confidence IOCs mentioned: CONSCTLX.exe SHA-256 bec369597633eac7cc27a698288e4ae8d12bdd9b01946e73a28e1423b17252b1; related C2 indicators observed/listed include vhs.delrosal.net, tumama.hns.to, blackice.sol-domain.org, codegiant.io (specific download path), 504e1a42.host.njalla.net, and 185.241.208.115 (C2 status noted as unconfirmed in the report, but recommended to block). Additional hunting indicators include the HKLM\Software<random GUID> encoded PowerShell persistence and scheduled tasks under C:\Windows\Defrag.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A secondary downloader dropped by a trojanized eScan update component (Reload.exe) during a supply-chain compromise; it is used to retrieve additional payloads from attacker-controlled infrastructure and helps disable/impair eScan by tampering with registry/files/update configuration and blocking update servers via hosts-file changes.
Final-stage payload delivered by the malicious update chain; functions as a backdoor and persistent downloader, enabling ongoing access and retrieval of further payloads from attacker-controlled infrastructure.
A persistent downloader/backdoor dropped via a trojanized eScan update. It establishes persistence (scheduled tasks and registry-based encoded PowerShell payload), tampers with hosts file and eScan registry/configuration to block AV updates (anti-remediation), and connects to attacker-controlled C2 infrastructure for additional payloads.
A 64-bit backdoor delivered via a trojanized eScan update chain; provides full remote access on compromised endpoints and is dropped by the replaced/signed Stage 1 component (Reload.exe).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.